Leevio's vulnerability footprint concentrates in the Happy Addons for Elementor plugin ecosystem, a niche but strategically important component within WordPress website builders that extends functionality for page layout and design. The recurring disclosures center on application-layer input-handling and access-control weaknesses, specifically cross-site scripting vulnerabilities and missing authorization checks, which are characteristic of plugin-based architectures where security boundaries between core and extension code can be porous. Defenders deploying Elementor-based sites should treat plugin updates from this vendor as part of routine WordPress hardening; current severity, exploitation status, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leevio over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48045HIGH Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This i | Nov 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-24833HIGH Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from n/a through <= 3.10.1. | May 8, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-2787MEDIUM The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to ins | Apr 9, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-10538MEDIUM The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to | Nov 12, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-47357MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Stored X | Oct 6, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-4391MEDIUM The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 | May 16, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-1366MEDIUM The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions u | Mar 7, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-0838MEDIUM The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and includi | Feb 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-51676MEDIUM Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.9.1.1. | Dec 29, 2023 | 6.5 | 18 | NO | NO |
CVE-2024-6627MEDIUM The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due t | Jul 27, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leevio.
Media articles that mention a CVE ID that affects a product developed by Leevio — matched by CVE ID, not by vendor name.